Privacy Policy
How we collect, use, and protect your personal information
Effective Date: February 1, 2025
Last Updated: August 9, 2026
Website: https://xhack.io
Contact Email: support@xhack.io
1. Introduction
XHack("we," "us," or "our") operates the xhack.io website, the XHack AI agent application, the XHack AI web interface, and related cybersecurity services (collectively, the "Platform"). This Privacy Policy describes what information we collect, what we deliberately do not collect, how we use and protect it, and what rights you have.
We are a cybersecurity firm. Privacy and data protection are not just legal requirements for us; they are the basis of the trust our clients place in us. This policy reflects that, including where it means saying plainly that a control has limits.
The XHack AI command-line interface (CLI) has been discontinued. References in this policy to the "Agent" mean the XHack AI agent graphical application that runs on hardware you control.
2. Who Is Responsible for Your Data
For individual accounts, marketing, website visitors, verification, and billing, XHack is the data controller.
Where an organization (a "Tenant") holds a company or enterprise subscription and administers seats for its team, the Tenant is the controller of its own team and engagement data, and XHackacts as a processor for that data under the Tenant's agreement. Verification records for each individual seat holder, and any Incident Records, are processed by XHack as controller, because they exist to enforce our own access rules and legal obligations. Tenant administrators can see the account status, seat assignment, verification state, and usage metering of the seats they administer.
User Verification & Safe Harbour
XHack verifies every user before granting access. Individuals are verified through government-issued identification and cybersecurity credentials. Organizations are verified through the identification of their authorized representative and their business documentation. This verification is a condition of access, not an optional step, and it is the reason we hold identity documents at all.
Verification is one of three layers. Access control decides who gets in. Runtime guardrails watch the shape of activity once a session is running and can end it mid-use. An Incident Record is created only when those guardrails trigger an enforcement action, so that the decision can be reviewed. We do not keep a running log of your Agent activity, and we do not store the chats of your local Agent sessions.
We are deliberate about the trade-off: we hold more identity data than a typical SaaS product, and far less activity data. That is the shape of the model, and this policy sets out both halves of it.
3. Information We Collect
3.1 Account information
When you register for an account, we collect:
- Full name
- Email address
- Username and password (hashed cryptographically, never stored in plaintext)
- Organization name and role, where applicable
- Contact details you choose to provide, such as a phone number
3.2 Identity verification data, individuals
Before an individual account is activated, we collect and review:
- A government-issued identification document (such as a passport, national ID card, or driving licence), including the identifiers printed on it, and its images
- Cybersecurity certifications and professional context, for example OSCP, OSCE, OSWE, CREST, or CEH certificates, employer or security-team affiliation, bug bounty platform profiles, or comparable evidence of a legitimate security function
- The outcome of our review, and the date it was performed
Identification documents may contain data that is treated as sensitive in some jurisdictions (for example nationality or place of birth). We collect them only to confirm that you are who you say you are, we do not use them for any other purpose, and we ask for your explicit consent where the law requires it.
3.3 Business verification data, companies and tenants
Before a company or tenant account is activated, we collect and review:
- A government-issued identification document for the authorized representative who registers and administers the account
- Business documentation evidencing that the organization is legitimate, which may include certificate of incorporation or registration, trade licence, tax or VAT registration, proof of registered address, and evidence of the representative's authority to act for the organization
- The outcome of our review, and the date it was performed
3.4 Verification interview recordings
Verification may include a live video interview to confirm identity and intent. Where a call is recorded, we ask for your consent before the recording starts, and we record that you gave it. If you decline, we cannot complete that verification step and access cannot be granted. Recordings are used solely to evidence the verification decision and are subject to the retention periods in Section 8.
3.5 Operational and billing data
To run, secure, and bill for the Platform, we process:
- Usage metering, request counts, token consumption, and plan entitlement usage
- Session metadata, sign-in events, session start and end timestamps, session duration, IP address, and device or client version
- Technical error reports needed to diagnose faults and keep the Platform reliable
- Transaction records, amount, date, currency, plan, and invoice history. Card and bank details are handled by our payment processors and are never stored on our servers
- Support correspondence you send us, and our replies
- Contact form submissions, including any company name and message you provide
3.6 Guardrail signals
While a session is running, the Platform evaluates contextual signals to assess whether the activity still matches the authorized, in-scope work the account was verified for. This evaluation is described in Section 5. It is performed in real time and is not retained as a running record. Unless an enforcement action is triggered, no record of the evaluation is kept.
3.7 Professional service engagement data
When you engage our professional services (VAPT, Red Teaming, SOC, and similar), we process what the engagement requires:
- Target system information as defined in the scope of work
- Network and infrastructure details necessary for authorized testing
- Vulnerability findings, evidence, and assessment results
- Communication records related to the engagement
Engagement data is handled under strict confidentiality, is never shared with third parties without your written consent, is never used for marketing, and is never used to train AI models.
4. What We Do Not Collect or Store
To be explicit about the commitments that matter most on this Platform:
- We do not store the chats of your local XHack AI agent sessions. The Agent runs on your machine. Prompts, responses, tool invocations, tool outputs, scan results, findings, and generated files stay there unless you deliberately send them to us or a third party
- We do not keep a running activity log of what you do in the Agent. The only record of Agent activity we create is the Incident Record described in Section 5.3, generated when the guardrails trigger an enforcement action
- We do not use your data, prompts, outputs, or engagement findings to train AI models
- We do not sell, rent, or trade personal data, and we do not work with data brokers
- We do not build advertising profiles or track you across other websites
- We do not perform automated facial recognition or biometric matching against your identification documents or interview recordings; verification is reviewed by our team
- We do not store card numbers or bank account details on our servers
Because we do not hold your Session Content, we cannot recover it for you, produce it in response to a request from you, or disclose it to anyone else, including in response to a legal demand. There is nothing on our side to produce.
5. Runtime Guardrails and Incident Records
5.1 What is monitored
XHackAI watches for context, not content. If a session that started as an authorized, in-scope engagement starts drifting toward something outside that scope, activity that looks like it is targeting a system with no authorization on file, or a request pattern that reads as harmful rather than defensive, the Platform can detect that pivot in real time. This is not a keyword filter, and it is not a general surveillance mechanism: it is an assessment of whether a verified user's activity still matches the work they were vetted for.
5.2 What happens to those signals
Guardrail evaluation happens as the session runs. Where no enforcement action is triggered, the evaluation is transient and no record of it is retained. We do not build behavioural profiles from it, we do not use it for marketing or product analytics, and we do not share it with third parties.
5.3 Incident Records
When the guardrails trigger an enforcement action, typically terminating the session and locking the account, we create an Incident Record so the decision can be justified and reviewed. An Incident Record typically contains:
- The account and, where applicable, tenant identifier
- The date, time, and session identifier
- The signals and contextual indicators that triggered the action
- The enforcement action taken, and the outcome of any subsequent review
Incident Records are used to review and, where appropriate, reverse the decision; to prevent repeat abuse; to establish, exercise, or defend legal claims; and to comply with legal obligations. They may be disclosed to law enforcement, a regulator, or an affected system owner where we consider it necessary or are legally required to do so.
5.4 Human review of automated decisions
An enforcement action may be triggered automatically. If a lockout affects you, you can request human review by writing to support@xhack.io. A member of our team will review the Incident Record together with any authorization evidence you provide, and you may contest the outcome.
5.5 The limits of these controls
We do not claim these controls are infallible. Detection is probabilistic: it can produce false positives that interrupt legitimate work, and it can miss genuine misuse. Verification can be socially engineered, and credentials can be stolen. What the model does is raise the cost of abuse and create evidence when it happens. We would rather say that plainly than imply a guarantee we cannot make.
6. How We Use Your Information
We use personal data for the following purposes and no others:
- Verifying your identity, professional standing, or business legitimacy before granting access
- Creating, administering, and securing your account
- Delivering the Platform and the professional services you have engaged
- Metering usage, processing payments, and managing subscriptions
- Detecting, investigating, and acting on misuse of the Platform
- Responding to support requests and technical enquiries
- Sending critical service notifications such as security advisories and maintenance windows
- Understanding aggregate website usage, where you have consented to analytics
- Complying with legal obligations and responding to lawful requests
We do not use your personal data for behavioural profiling, advertising, or any purpose unrelated to the services you have engaged.
7. Legal Bases for Processing
Where data protection law such as the GDPR or UK GDPR applies, we rely on:
- Contract: account creation and administration, service delivery, metering, billing, and support
- Legal obligation: retaining financial records, responding to lawful requests, and meeting anti-abuse and sanctions obligations
- Legitimate interests: verifying users before granting access to powerful security tooling, operating the runtime guardrails, creating and retaining Incident Records, securing our infrastructure, and preventing misuse. We have assessed these interests against your rights and consider them proportionate given the nature of the capability being protected
- Consent: recording a verification interview, optional communications, and non-essential cookies. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out
- Explicit consent or substantial public interest: where an identification document contains data treated as sensitive in your jurisdiction, to the extent required by local law
- Legal claims: retaining verification records and Incident Records for the establishment, exercise, or defence of legal claims
8. Data Retention
- Account data, retained while your account is active, and deleted or de-identified within 30 days of closure on request, subject to the exceptions below
- Verification records (identification documents, certifications, business documents, interview recordings, and the review outcome), retained while your account is active and for a limited period afterwards so that we can evidence who we granted access to and why. We keep the review outcome and a minimal record of the documents relied upon for longer than the document images themselves, and we delete the images once they are no longer needed for that purpose
- Guardrail signals, not retained where no enforcement action is triggered
- Incident Records, retained for as long as necessary to prevent repeat abuse and to establish, exercise, or defend legal claims, which will normally be longer than the life of the account
- Session Content from the Agent, not retained by us at all
- Engagement data, retained for the period specified in your service agreement, then securely destroyed by cryptographic erasure or physical destruction
- Billing records, retained as required by applicable tax and financial regulation
- Support correspondence, retained for 12 months after resolution
If you would like the specific retention period that applies to your account and jurisdiction, contact us and we will tell you.
9. Sharing and Disclosure
We do not sell personal data. We share it only in these circumstances:
- Service providers: cloud infrastructure and hosting, payment processing, email delivery, identity and document verification support, and analytics. Each is vetted, bound by a data processing agreement, and given only the minimum data needed
- Tenant administrators:for seats under a company or enterprise subscription, the Tenant's administrators can see seat status, verification state, and usage metering for the seats they administer
- Law enforcement and regulators: where we are legally required to disclose, or where we consider disclosure necessary in connection with an Incident Record, unlawful activity, or a threat to safety. We assess each request and disclose only what is required
- Professional advisers and corporate transactions: to our auditors and legal advisers under confidentiality, and to a successor entity in a merger, acquisition, or asset sale, subject to this policy continuing to apply
10. Cookies, Analytics, and Tracking
We use essential cookies required for secure authentication and session management. These cannot be switched off without breaking sign-in.
On our public website we also use Google Analytics to understand aggregate traffic and page performance. This is a third-party analytics service that sets its own identifiers. You can accept or decline analytics through our cookie banner and change your choice at any time at Cookie Settings. Declining analytics does not affect your access to the Platform.
We do not use advertising cookies, retargeting pixels, or cross-site tracking, and we do not participate in ad networks. We do not run analytics inside the Agent.
11. Data Storage and Security
As a cybersecurity firm, we hold ourselves to the standards we assess others against:
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Passwords are hashed with industry-standard algorithms and never stored in plaintext
- Verification documents are stored with restricted access and are viewable only by the personnel who perform verification
- Access to production systems is limited to authorized personnel under role-based access control, with multi-factor authentication
- Infrastructure is monitored for unauthorized access and anomalous activity
- We conduct regular security assessments of our own infrastructure
No system is perfectly secure. We do not claim ours is. We design so that a compromise of our Platform does not expose your Session Content, because we never hold it.
12. Engagement Data Confidentiality
Data collected during professional service engagements, VAPT reports, vulnerability findings, network diagrams, credentials, configuration details, receives the highest level of protection. It is accessible only to the researchers assigned to your engagement, is never used to train AI models, is never shared with other clients, and is not retained beyond the contractually agreed retention period. On expiry, it is securely destroyed using cryptographic erasure or physical destruction.
13. Local Models and Bring Your Own Key (BYOK)
The Agent supports local model execution and Bring Your Own Key (BYOK) configurations. With local models, processing happens entirely on your own hardware and no prompts or responses leave your machine. With BYOK, data flows directly between your machine and the third-party provider using your own API key; XHackdoes not intercept, log, or store it. The third-party provider's own privacy terms govern that exchange, and you are responsible for reviewing them.
14. International Data Transfers
Your data may be processed in countries other than your own, including by the service providers listed in Section 9. Where data is transferred out of the UK, EEA, or another region with transfer restrictions, we rely on an appropriate safeguard such as standard contractual clauses together with supplementary measures. We do not transfer engagement data outside the jurisdiction agreed in your service agreement without your explicit written consent.
15. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: obtain a copy of the personal data we hold about you
- Rectification: have inaccurate or incomplete data corrected
- Erasure: have your personal data deleted, subject to the limits below
- Portability: receive your data in a structured, machine-readable format
- Restriction: ask us to restrict processing in certain circumstances
- Objection: object to processing based on legitimate interests
- Withdraw consent: withdraw consent you previously gave, including for analytics or an interview recording
- Human review: obtain human review of, and contest, an automated enforcement decision, as described in Section 5.4
- Complain: lodge a complaint with your local data protection supervisory authority
Limits on erasure. We cannot delete data we are required to keep, and we will not delete records whose whole purpose is accountability. Specifically, we may retain verification records and Incident Records after account closure where necessary to establish, exercise, or defend legal claims, to comply with a legal obligation, or to prevent a user who was removed for abuse from simply re-registering. Where we decline an erasure request on that basis, we will tell you why and restrict the data to that purpose only.
To exercise any right, contact support@xhack.io. We may need to verify your identity before acting. We respond to legitimate requests within 30 days, or tell you if we need longer.
16. Data Breach Notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where the law requires it, notify affected users directly with a description of what happened, what data was involved, and what steps we are taking.
17. Children's Privacy
The Platform and our services are not intended for anyone under 18. We do not knowingly collect personal information from minors, and our verification process is designed to confirm age. If we learn we have collected data from someone under 18, we will delete it promptly.
18. Responsible Use
The Platform and the Agent are intended exclusively for authorized, ethical, and lawful cybersecurity operations conducted with documented permission. Users are solely responsible for holding appropriate authorization before testing any system. XHack is not liable for misuse of the Platform or for unauthorized activity conducted with our tools. Our Terms of Service set out the full framework, including the enforcement actions described in Section 5 of this policy.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, services, or applicable law. When we make material changes, we will notify you by email or through a prominent notice on the Platform. The "Last Updated" date above indicates the most recent revision. Continued use after changes take effect constitutes acceptance.
20. Contact
For any question about this policy, to exercise a right, or to raise a concern about how we handle your data:
- Email: support@xhack.io
- Website: https://xhack.io
If you are not satisfied with our response, you have the right to complain to your local data protection supervisory authority.